Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30979
HistoryJun 16, 2021 - 1:50 p.m.

Man-in-the-middle (MITM)

2021-06-1613:50:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
32

0.001 Low

EPSS

Percentile

29.5%

bluez:sid is vulnerable to man-in-the-middle attack. Bluetooth LE and BR/EDR secure pairing in Bluetooth may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.